cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
195
Views
5
Helpful
1
Replies

On ASA5525 with vanilla setup, need to place ACL on outside int?

jmaxwellUSAF
Enthusiast
Enthusiast

Hi.

On an ASA5525 within a vanilla configuration, because of default "0, 50, 100" security levels, and also because default is "sysopt connection permit-vpn",

Is there a general need to place any ACL on the outside interface?

Thank you.

1 Accepted Solution

Accepted Solutions

Rob Ingram
VIP Master VIP Master
VIP Master

@jmaxwellUSAF No. The outside interface would as default have a security level of 0, the inside interface with a security level of 100, traffic from lower security level (0) to higher (100) would, by default be denied. You only need an ACL inbound on the outside interface if you wish to selectively permit traffic.

"sysopt connection permit-vpn" is applicable to ignoring the interface ACL for encrypted traffic (L2L or RAVPN).

View solution in original post

1 Reply 1

Rob Ingram
VIP Master VIP Master
VIP Master

@jmaxwellUSAF No. The outside interface would as default have a security level of 0, the inside interface with a security level of 100, traffic from lower security level (0) to higher (100) would, by default be denied. You only need an ACL inbound on the outside interface if you wish to selectively permit traffic.

"sysopt connection permit-vpn" is applicable to ignoring the interface ACL for encrypted traffic (L2L or RAVPN).

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers